The short answer: PIPEDA requires an organization that experiences a breach of security safeguards to assess it against the real-risk-of-significant-harm standard and where that risk exists, to report to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible. Records of every breach must be kept for 24 months. This is informational, not legal advice.
Scope of This Guide
This is an operational playbook for the breach-reporting duty under Canada's Personal Information Protection and Electronic Documents Act, known as PIPEDA. It is the how-to-comply companion to our broader PIPEDA compliance guide: that guide gives the overview of the ten fair information principles and general obligations, while this one is the step-by-step of what to actually do after a breach, how to make the reporting decision and what to file with whom and by when.
The material below reflects the mandatory breach-reporting requirements that have been in force under PIPEDA since November 2018 and the guidance published by the Office of the Privacy Commissioner of Canada. It is informational and general in nature. It is not legal advice and the specific obligations for any organization should be confirmed with qualified counsel and against the current text of the law.
What Counts as a Reportable Breach
PIPEDA is concerned with a breach of security safeguards, which the law frames as the loss of, unauthorized access to or unauthorized disclosure of personal information resulting from a failure of an organization security safeguards. That covers the obvious cases such as a hacked database or a ransomware theft and less obvious ones such as a lost laptop or a mis-sent email containing personal information.
Not every breach triggers notification, but every breach triggers a duty to assess and to record. The assessment step is where the organization determines whether the notification obligations apply, using the standard described next.
The RROSH Decision: How to Determine Real Risk of Significant Harm
The threshold for notification is whether the breach creates a real risk of significant harm to an individual, a standard the Office of the Privacy Commissioner describes as having two parts. First, could the breach create significant harm. Second, is there a real risk that the harm will occur. Both parts have to be considered.
The Office of the Privacy Commissioner explains that significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business or professional opportunities, financial loss, identity theft, negative effects on a credit record and damage to or loss of property. Assessing the real risk involves factors such as the sensitivity of the information and the probability that it will be misused. Where both parts are met, the notification duties are engaged.
Reporting to the OPC: What the Report Must Contain
When a breach meets the real-risk-of-significant-harm standard, the organization must report it to the Office of the Privacy Commissioner of Canada. The report is expected as soon as feasible after the organization determines that the breach has occurred and it describes the circumstances of the breach, the personal information involved, the number of individuals affected where known, the steps taken to reduce harm and the steps taken to notify individuals.
As soon as feasible is a promptness standard rather than a fixed number of days and for a serious breach it can mean acting quickly. The practical implication is that an organization should not wait until every detail is known before reporting. It reports on the facts it has and updates the Office as the investigation develops.
Notifying Individuals: When to Notify
Alongside the report to the Office of the Privacy Commissioner, the organization must notify the affected individuals, also as soon as feasible. The notice has to contain enough information to let a person understand the significance of the breach and take steps to reduce the risk of harm or mitigate it, such as changing a password or watching for fraud.
Timing is the operational trap. The duty to notify individuals runs alongside the report to the Office of the Privacy Commissioner, so an organization should not treat the individual notice as a later phase to be perfected once the investigation is complete. It notifies as soon as feasible on the facts it has and follows up with more detail as the picture firms up. Delaying the notice to draft a perfect message is itself a compliance risk, because the standard is promptness rather than polish.
Notifying Other Organizations
PIPEDA also requires notifying other organizations or government institutions where doing so may reduce the risk of harm or mitigate it. A common example is notifying a payment processor, a credit bureau or law enforcement when their involvement could help protect the affected individuals.
This third-party notification runs in parallel with the report to the Office and the notice to individuals and it is part of the same objective of limiting harm from the breach.
The 24-Month Record-Keeping Rule
A requirement that is easy to overlook is record-keeping. PIPEDA requires an organization to keep a record of every breach of security safeguards, not only the ones that meet the real-risk-of-significant-harm threshold and to retain those records for 24 months. The Office of the Privacy Commissioner can ask to see them to verify that the organization has complied with its reporting obligations.
In practice this means maintaining a breach log that captures each incident, the assessment of harm and the actions taken. The record for a breach judged below the threshold matters too, because it documents the reasoning behind the decision not to notify, which is exactly what the Office may later review.
Penalties and Enforcement
PIPEDA attaches consequences to the breach obligations. Knowingly failing to report a breach that meets the threshold to the Office, failing to notify affected individuals or failing to maintain the required records can expose an organization to significant fines under the Act. Beyond the statutory penalty, the reputational cost of a mishandled breach and any resulting civil exposure are often the larger risks.
Enforcement aside, the underlying point of the regime is to ensure that people whose information is exposed learn about it in time to protect themselves. An organization that treats notification as a genuine duty rather than a formality tends to handle the whole incident better.
A Practical Post-Breach Notification Timeline
Turning the law into action, a defensible sequence looks like this. Contain the breach and preserve the evidence. Assess the breach against the real-risk-of-significant-harm standard, documenting the reasoning. If the threshold is met, report to the Office of the Privacy Commissioner as soon as feasible and notify affected individuals as soon as feasible, with the content the law requires. Notify any third parties that can reduce harm. Record the breach and retain the record for 24 months regardless of the outcome.
Every step in that sequence depends on knowing the facts of the breach, which is where forensics comes in. A forensic investigation establishes what data was affected and how many individuals, which is exactly what the harm assessment and the notifications require. Sherlock Forensics supports the factual side of this process through its incident response service and our analysis of the cost of a breach for a mid-market company shows why getting the scope right matters financially as well as legally. For the authoritative requirements, consult the Office of the Privacy Commissioner of Canada directly and seek legal advice on your organization specific obligations.
What the Individual Notice Must Contain
The notice to an affected individual is not a free-form apology; the law expects it to contain specific, useful information. The Office of the Privacy Commissioner indicates that a notification should describe the circumstances of the breach, when it occurred, the personal information involved, the steps the organization has taken to reduce the risk of harm and the steps the individual can take to protect themselves, along with a way to contact the organization for more information.
The practical test is whether the notice actually equips the person to act. A notice that says a breach occurred but does not say what was exposed leaves the individual unable to judge their risk, which defeats the purpose. A strong notice is specific about the data involved and concrete about the protective steps, such as changing a password, watching for fraud or placing a fraud alert, matched to the type of information exposed.
Direct notification to the individual is expected where feasible, by a method such as email, letter or telephone, with indirect notification like a public notice reserved for situations where direct contact is not possible or would itself cause further harm. Getting the content and the method right is part of the operational duty, not an afterthought and it is one more reason the underlying forensic scoping has to be accurate before the notice goes out.